CVE-2026-105857: Payload: RCE in Payload Form Builder
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely on the server. This issue is fixed in versions 3.90.0 and 4.0.0-canary.34.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@payloadcms/plugin-form-builderto a version that resolves this vulnerability.Fixed in 3.90.0 - Upgrade
Upgrade
@payloadcms/plugin-form-builderto a version that resolves this vulnerability.Fixed in 4.0.0-canary.34
Event History
Frequently Asked Questions
Which deployments are affected?
Deployments using npm/@payloadcms/plugin-form-builder before version 3.90.0 are affected. Canary deployments are affected if they use a version before 4.0.0-canary.34.
Does exploitation require authentication or user interaction?
No. The supplied vector indicates network-accessible exploitation with low attack complexity, no privileges required, and no user interaction required.
What should be done to remediate the issue?
Upgrade @payloadcms/plugin-form-builder to version 3.90.0 or later. Canary users should upgrade to 4.0.0-canary.34 or later.
What impact can successful exploitation have?
A crafted form submission can result in remote code execution on the server. The provided severity vector indicates high confidentiality, integrity, and availability impact, with scope changed.